{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sylius-2.1.x--2.1.16-2.2.x--2.2.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-100870"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sylius (\u003c 1.12.25, \u003c 1.13.17, \u003c 1.14.20, \u003c 2.1.16, \u003c 2.2.9)","Sylius (2.1.x \u003c 2.1.16, 2.2.x \u003c 2.2.9)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","account-takeover","authentication-bypass","privilege-escalation","financial-fraud","e-commerce","cve-2026-100872"],"_cs_type":"advisory","_cs_vendors":["Sylius"],"content_html":"\u003cp\u003eSylius versions released prior to 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 contain a critical vulnerability in the password reset workflow. The application incorrectly utilizes the HTTP 'Host' header provided in an incoming password reset request to construct the password reset link sent to the user. An unauthenticated attacker can exploit this by injecting a malicious domain into the 'Host' header while initiating a reset request for a target administrator's email address. The resulting reset email contains a link pointing to an attacker-controlled server, facilitating the theft of the reset token and leading to full account takeover. This vulnerability poses a significant risk to administrative access and underscores the necessity of validating input derived from HTTP headers against an allowlist of expected domains.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target administrator's email address associated with the Sylius instance.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a password reset request via the legitimate application endpoint (e.g., /password-reset/request).\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the outgoing HTTP request using a proxy or intercepting tool.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the 'Host' header field in the request to point to an attacker-controlled domain.\u003c/li\u003e\n\u003cli\u003eThe Sylius backend processes the request and uses the malicious 'Host' header to generate the URL for the password reset token.\u003c/li\u003e\n\u003cli\u003eThe application sends the password reset email to the legitimate administrator, containing the poisoned, attacker-controlled link.\u003c/li\u003e\n\u003cli\u003eThe administrator clicks the malicious link, sending the reset token to the attacker's infrastructure.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the intercepted token to reset the administrator's password and gain unauthorized administrative access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform full account takeover of administrative accounts. This grants attackers unauthorized access to the Sylius management dashboard, allowing for data exfiltration, system configuration changes, and further persistence within the application environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching affected Sylius installations to the latest secure versions. For environments unable to patch immediately, implement strict validation of the 'Host' header at the web application firewall (WAF) or load balancer level to ensure only authorized hostnames are accepted for administrative requests.\u003c/p\u003e\n","date_modified":"2026-09-27T15:07:38Z","date_published":"2026-09-27T15:07:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sylius-password-reset-poisoning/","summary":"Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 are vulnerable to a password reset poisoning attack, allowing unauthenticated attackers to hijack administrator accounts via Host header manipulation.","title":"Host Header Injection in Sylius Password Reset Mechanism","url":"https://feed.craftedsignal.io/briefs/2026-09-sylius-password-reset-poisoning/"}],"language":"en","title":"CraftedSignal Threat Feed - Sylius (2.1.x \u003c 2.1.16, 2.2.x \u003c 2.2.9)","version":"https://jsonfeed.org/version/1.1"}